---
id: CVE-2025-59940
title: >-
  mkdocs-include-markdown-plugin: mkdocs-include-markdown-plugin susceptible to
  unvalidated input colliding with substitution placeholders (C…
summary: >-
  There is an improper input validation flaw in the python
  `mkdocs-include-markdown-plugin` package. Under certain conditions
  placeholders are not properly validated and may collide with other data
  elements resulting in inconsistent output.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'
cvssSource: vendor
cwe: CWE-20
vendor: Red Hat
product: Multicluster Engine for Kubernetes
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - multicluster_engine_for_kubernetes
  - openshift_container_platform 4
patched:
  - mkdocs-include-markdown-plugin 7.1.8
published: '2025-09-29'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T03:37:46+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59940.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59940.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-59940'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2400372'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-59940'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59940'
  - url: >-
      https://github.com/mondeja/mkdocs-include-markdown-plugin/commit/7466d67aa0de8ffbc427204ad2475fed07678915
  - url: 'https://github.com/mondeja/mkdocs-include-markdown-plugin/issues/274'
  - url: 'https://github.com/mondeja/mkdocs-include-markdown-plugin/pull/277'
  - url: >-
      https://github.com/mondeja/mkdocs-include-markdown-plugin/security/advisories/GHSA-v39m-5m9j-m9w9
  - url: 'https://github.com/mondeja/mkdocs-include-markdown-plugin'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00341
epssPercentile: 0.24851
aliases:
  - GHSA-v39m-5m9j-m9w9
  - PYSEC-2026-1632
ecosystem: pip
ingestedAt: '2026-07-08T18:25:53.057Z'
---

## Overview

There is an improper input validation flaw in the python `mkdocs-include-markdown-plugin` package. Under certain conditions placeholders are not properly validated and may collide with other data elements resulting in inconsistent output.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4 · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4 · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59940.json)

**mkdocs-include-markdown-plugin: mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders** — rated Moderate by Red Hat. Released 2025-09-29, updated 2026-09-23.

Affected:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- Multicluster Engine for Kubernetes
- Red Hat OpenShift Container Platform 4

No fix planned:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- Multicluster Engine for Kubernetes
- Red Hat OpenShift Container Platform 4

## Remediation

Fix deferred

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2025-59940)

Affected packages:

- `mkdocs-include-markdown-plugin < 7.1.8`

Patched in:

- `mkdocs-include-markdown-plugin 7.1.8`

Source: https://osv.dev/vulnerability/GHSA-v39m-5m9j-m9w9
